US2020127850A1PendingUtilityA1

Certifying a trusted platform module without privacy certification authority infrastructure

Assignee: INTEL CORPPriority: Dec 20, 2019Filed: Dec 20, 2019Published: Apr 23, 2020
Est. expiryDec 20, 2039(~13.4 yrs left)· nominal 20-yr term from priority
H04L 2209/127H04L 9/3247H04L 9/3242H04L 9/0897G06F 2221/033H04L 9/3234H04L 9/30G06F 21/53G06F 2221/2149
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method comprises receiving, in a trusted execution environment (TEE), an attestation public key and one or more endorsement credentials for a trusted platform module, inspecting the one or more endorsement credentials for the trusted platform module, generating an attestation that the attestation public key resides within the trusted platform module identified by the one or more endorsement credentials, the attestation comprising at least a portion of the public attestation key, encrypting, in the trusted execution environment, at least a component of the attestation to generate an attestation key activation blob, forwarding the attestation key activation blob to the platform module, and receiving, from the platform module, a response that varies based on whether at least a portion of the public attestation key in the attestation key activation blob matches a public attestation key on the platform module.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, in a trusted execution environment (TEE), a first attestation public key representing a trusted platform module, and one or more endorsement credentials for the trusted platform module;   inspecting the one or more endorsement credentials for the trusted platform module;   using a second attestation key representing the TEE to generate an attestation that the first attestation public key resides within the trusted platform module identified by the one or more endorsement credentials, the attestation comprising at least a portion of the public attestation key;   encrypting, in the trusted execution environment, at least a component of the attestation to generate an attestation key activation blob;   forwarding the attestation key activation blob to the trusted platform module; and   receiving, from the trusted platform module, a response comprising one of:
 a first value in the event that the at least a portion of the public attestation key in the attestation key activation blob matches a public attestation key on the trusted platform module, or 
 a second value in the event that the at least a portion of the public attestation key in the attestation key activation blob fails to match a public attestation key on the platform module. 
   
     
     
         2 . The method of  claim 1 , further comprising:
 reconstructing a TEE attestation in the event the response from the trusted platform module comprises the first value.   
     
     
         3 . The method of  claim 2 , wherein the TEE attestation comprises the public attestation key, the one or more endorsement credentials, and a signature generated by the trusted execution environment. 
     
     
         4 . The method of  claim 1 , wherein the attestation key activation blob comprises at least one of a signature on the attestation or the entire attestation. 
     
     
         5 . The method of  claim 1 , further comprising:
 generating a report comprising at least a portion of the attestation key activation blob; and   sending the report to a quoting enclave.   
     
     
         6 . The method of  claim 5 , wherein the attestation key activation blob comprises at least one of a message authentication code (MAC) or a portion of the report generated by the trusted execution environment. 
     
     
         7 . The method of  claim 1 , wherein:
 the trusted execution environment and the trusted platform module reside on the same platform.   
     
     
         8 . An apparatus comprising:
 a processor; and   a computer readable memory comprising instructions which, when executed by the processor, cause the processor to:
 receive, in a trusted execution environment (TEE), a first attestation public key representing a trusted platform module, and one or more endorsement credentials for the trusted platform module; 
 inspect the one or more endorsement credentials for the trusted platform module; 
 use a second attestation key representing the TEE to generate an attestation that the first attestation public key resides within the trusted platform module identified by the one or more endorsement credentials, the attestation comprising at least a portion of the public attestation key; 
 encrypt, in the trusted execution environment, at least a component of the attestation to generate an attestation key activation blob; 
 forward the attestation key activation blob to the trusted platform module; and 
 receive, from the trusted platform module, a response comprising one of:
 a first value in the event that the at least a portion of the public attestation key in the attestation key activation blob matches a public attestation key on the trusted platform module, or 
 a second value in the event that the at least a portion of the public attestation key in the attestation key activation blob fails to match a public attestation key on the platform module. 
 
   
     
     
         9 . The apparatus of  claim 8 , comprising instructions which, when executed by the processor, cause the processor to:
 generate a TEE attestation in the event the response from the trusted platform module comprises the first value.   
     
     
         10 . The apparatus of  claim 9 , wherein the TEE attestation comprises the public attestation key, the one or more endorsement credentials, and a signature generated by the trusted execution environment. 
     
     
         11 . The apparatus of  claim 8 , wherein the attestation key activation blob comprises at least one of a signature on the attestation or the entire attestation. 
     
     
         12 . The apparatus of  claim 8 , comprising instructions which, when executed by the processor, cause the processor to
 generate a report comprising at least a portion of the attestation key activation blob; and   send the report to a quoting enclave.   
     
     
         13 . The apparatus of  claim 12 , wherein the attestation key activation blob comprises at least one of a message authentication code (MAC) or a portion of the report generated by the trusted execution environment. 
     
     
         14 . The apparatus of  claim 8 , wherein:
 the trusted execution environment and the trusted platform module reside on the same platform.   
     
     
         15 . One or more computer-readable storage media comprising instructions stored thereon that, in response to being executed, cause a computing device to:
 receive, in a trusted execution environment (TEE), a first attestation public key representing a trusted platform module, and one or more endorsement credentials for the trusted platform module;   inspect the one or more endorsement credentials for the trusted platform module;   use a second attestation key representing the TEE to generate an attestation that the first attestation public key resides within the trusted platform module identified by the one or more endorsement credentials, the attestation comprising at least a portion of the public attestation key;   encrypt, in the trusted execution environment, at least a component of the attestation to generate an attestation key activation blob;   forward the attestation key activation blob to the trusted platform module; and   receive, from the trusted platform module, a response comprising one of:
 a first value in the event that the at least a portion of the public attestation key in the attestation key activation blob matches a public attestation key on the trusted platform module, or 
 a second value in the event that the at least a portion of the public attestation key in the attestation key activation blob fails to match a public attestation key on the platform module. 
   
     
     
         16 . The one or more computer-readable storage media of  claim 16 , further comprising instructions stored thereon that, in response to being executed, cause the computing device to:
 generate a TEE attestation in the event the response from the trusted platform module comprises the first value.   
     
     
         17 . The one or more computer-readable storage media of  claim 15 , wherein the TEE attestation comprises the public attestation key, the one or more endorsement credentials, and a signature generated by the trusted execution environment. 
     
     
         18 . The one or more computer-readable storage media of  claim 15 , wherein the attestation key activation blob comprises at least one of a signature on the attestation or the entire attestation. 
     
     
         19 . The one or more computer-readable storage media of  claim 19 , further comprising instructions stored thereon that, in response to being executed, cause the computing device to
 generate a report comprising at least a portion of the attestation key activation blob; and   send the report to a quoting enclave.   
     
     
         20 . The one or more computer-readable storage media of  claim 19 , wherein the attestation key activation blob comprises at least one of a message authentication code (MAC) or a portion of the report generated by the trusted execution environment. 
     
     
         21 . The one or more computer-readable storage media of  claim 15 , wherein:
 the trusted execution environment and the trusted platform module reside on the same platform.

Join the waitlist — get patent alerts

Track US2020127850A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.